← Back to Attack / Defense Lab
OSI LAYER 2 // Data Link Layer

MAC Flooding

MAC flooding attempts to overflow a switch’s MAC address table so forwarding behavior becomes less selective.

PREMIUM RESOURCE
01 // HOW IT WORKS

Mechanism

When a switch cannot associate destinations reliably, it may flood frames more broadly within the relevant segment.

02 // DETECTION

Indicators to watch

Rapid growth in learned MAC addresses, table exhaustion alerts, unusual source-MAC churn, and increased unknown-unicast traffic.

03 // ATTACK FLOW

Concept diagram

01Switch port↓
02Many source MACs↓
03CAM table pressure↓
04Unknown-unicast flooding↓
05Port security
04 // PREVENTION

Defensive controls

Enable port security, limit learned MAC addresses, segment networks, use storm controls, and monitor switch telemetry.

05 // SECURITY TOOL

Recommended security control

Switch port-security monitoring

Use a virtual switch or isolated lab.

06 // DEFENSE TOOL

Defense tool

The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.

PREMIUMBuild Soon
◈
DEFENSE TOOL // BUILD SOONThe administrator can attach a file or external tool link from the private admin portal.
AUTHORIZED LEARNING

All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.